
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3930 is an unsafe navigation vulnerability in the Navigation component of Google Chrome on iOS that allows a remote attacker to bypass navigation restrictions via a crafted HTML page. It was reported by Povcfe of Tencent Security Xuanwu Lab on January 19, 2026, and patched on March 10, 2026, as part of the Chrome 146 stable channel release. The vulnerability affects Google Chrome on iOS prior to version 146.0.7680.71, and Microsoft Edge (Chromium-based) is also listed as an affected product. It carries a CVSS v3.1 base score of 5.3 (Medium) (Chrome Release, Feedly).
The vulnerability is classified under CWE-288 (Authentication Bypass Using an Alternate Path or Channel), indicating that Chrome's iOS navigation subsystem fails to properly enforce navigation restrictions through an alternative code path. An attacker can exploit this by serving a specially crafted HTML page to a victim, which triggers the unsafe navigation behavior without requiring any privileges or user interaction beyond visiting the page. The bug was tracked internally as Chromium issue 476898368 and awarded a $1,000 bounty, reflecting its medium severity classification (Chrome Release).
Successful exploitation allows a remote attacker to bypass Chrome's navigation security restrictions on iOS devices, potentially redirecting users to unintended destinations or circumventing browser controls designed to protect users from malicious sites. The impact is limited to integrity (CVSS integrity impact: Low), with no direct confidentiality or availability consequences. This could be leveraged as part of a broader attack chain — for example, to redirect users to phishing pages or bypass same-origin navigation controls (Feedly).
Google has addressed this vulnerability in Chrome 146.0.7680.71 for Linux and 146.0.7680.71/72 for Windows and Mac, released on March 10, 2026. Users running Google Chrome on iOS should update to version 146.0.7680.71 or later immediately. Microsoft Edge (Chromium-based) users should also apply the corresponding update from Microsoft. No configuration-based workarounds have been published; updating to the patched version is the only recommended remediation (Chrome Release, Microsoft MSRC).
The vulnerability was part of a broader Chrome 146 security update that addressed 29 security issues, including several Critical and High severity bugs, which received coverage from security news outlets such as GBHackers. The specific CVE-2026-3930 did not generate significant standalone commentary, consistent with its medium severity and lack of active exploitation. Downstream Linux distributions including Debian, Fedora, and openSUSE issued their own Chromium security advisories incorporating this fix (Chrome Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."